Installation

Splunk Universal Forwarder agent support for Amazon Linux 2023 x86/arm

vk2
New Member

Is splunk forwarder agent 9.2.0.1 supported on Amazon Linux 2023 x86/arm OS using RPM file. 

Got error while starting splunk service. 
tcp_conn_open_afux ossocket_connect failed with No such file or directory
tcp_conn_open_afux ossocket_connect failed with No such file or directory
tcp_conn_open_afux ossocket_connect failed with No such file or directory

Labels (1)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

UFs are supported on a relatively wide range of equipment and OS versions (and even if the current UF doesn't support your older hardware or OS release you can still use an older version of UF within the compatibility boundaries - and sometimes even beyond that but I wouldn't advise running UFs that old anyway).

if I'm not mistaken, the error is from the service trying to connect to a running splunkd instance.

Check your splunkd.log to see what's going on.

Also - how did you install that forwarder? RPM? Or just unpacked the tgz?

0 Karma

kiran_panchavat
Contributor

@vk2 You can check the below document, Splunk universal forwarder is compatible with Linux OS which is having kernel 4.x or higher. If you have kernel 3.x , Splunk supports this platform and architecture, but might remove support in a future release. 

https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements#Confirm_support_... 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...